PonyflashSAFE
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Generate images, videos, speech audio, and music through the PonyFlash Python SDK, and handle local media editing with FFmpeg.
Compatible with the Agent Skills open standard. Works with Claude Code, OpenClaw, Cursor, Codex, Gemini CLI, Windsurf, Cline and 40+ other AI agents.
Quick Install
Git (all agents)
git clone https://github.com/ponyflash/ponyflash-skill.git ponyflash
Then move the ponyflash folder into your agent's skills directory.
OpenClaw
# From ClawHub (if published) clawhub install ponyflash # Or manually git clone https://github.com/ponyflash/ponyflash-skill.git ~/.openclaw/skills/ponyflash
Claude Code
git clone https://github.com/ponyflash/ponyflash-skill.git .claude/skills/ponyflash
Cursor
git clone https://github.com/ponyflash/ponyflash-skill.git .cursor/skills/ponyflash
Skills Directory by Agent
What This Skill Does
This skill now combines PonyFlash cloud generation and local FFmpeg media processing.
4f3b4a2a472eOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
git clone https://github.com/ponyflash/ponyflash-skill.git ponyflash
git clone https://github.com/ponyflash/ponyflash-skill.git ~/.openclaw/skills/ponyflash
git clone https://github.com/ponyflash/ponyflash-skill.git .claude/skills/ponyflash
git clone https://github.com/ponyflash/ponyflash-skill.git .cursor/skills/ponyflash
pip install ponyflash
pip install ponyflash
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned | |
| openclaw | mentioned | |
| windsurf | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: ponyflash
description: >-
Generate images, videos, speech audio, and music using the PonyFlash Python SDK.
Also handle local media editing with FFmpeg, including clip, concat, transcode,
extract audio, frame capture, subtitle capability checks, and ASS subtitle prep.
Use when the user asks to create, generate, produce, edit, trim, merge, concatenate,
transcode, subtitle, or render AI-generated media content.
license: MIT
metadata:
author: ponyflash
version: "0.3.0"
---
# PonyFlash Skill
## Step 0: Decide Which Capability Path Applies
This skill now contains **two capability families**:
1. **Cloud generation via PonyFlash Python SDK**
- image generation
- video generation
- speech synthesis
- music generation
- model listing
- file management
- account / credits
- These tasks **require a valid PonyFlash API key**.
2. **Local media editing via FFmpeg toolchain**
- ffmpeg / ffprobe detection
- installation planning
- clip / concat / transcode
- extract audio / capture frame
- subtitle capability checks
- ASS subtitle generation and burn-in workflow
- These tasks **do NOT require a PonyFlash API key**, but they **do require local `ffmpeg` / `ffprobe` support**.
Before doing anything, classify the request:
- If the user is asking to **generate** media with PonyFlash models, follow the SDK path and require API key setup.
- If the user is asking to **edit or process local media**, follow the FFmpeg path and do dependency checks first.
- If the user wants an **end-to-end production workflow**, you may use both: generate assets with PonyFlash, then assemble or export with FFmpeg.
## Step 1A: API Key Setup for PonyFlash SDK Tasks
Only do this section when the request needs PonyFlash cloud capabilities.
**The FIRST time this skill is activated for a cloud generation task**, tell the user the following in your own words:
1. PonyFlash skill is ready to use.
2. It can handle:
- image generation
- video generation
- speech synthesis
- music generation
- local media editing with FFmpeg
3. For complex multi-step productions, there are **Creative Playbooks** in the `playbooks/` directory.
4. To use PonyFlash cloud generation, the user needs an API key:
- Register / log in at **https://www.ponyflash.com**
- Get API key at **https://www.ponyflash.com/api-key** (starts with `rk_`)
- Check credits at **https://www.ponyflash.com/usage**
- Paste the key back in the chat
**On subsequent SDK activations**, check whether `PONYFLASH_API_KEY` is set in the environment. If not, ask the user for the key again.
Once received, set it up:
```bash
export PONYFLASH_API_KEY="rk_xxx"
```
Then install the SDK:
```bash
pip install ponyflash
```
**Always verify the key works before any generation task:**
```python
from ponyflash import PonyFlash
pony_flash = PonyFlash(api_key="<key from user>")
balance = pony_flash.account.credits()
print(f"Balance: {balance.balance} {balance.currency}")
```
If verification fails:
- **Key invalid or missing** → direct user to https://api.ponyflash.com/api-key
- **Balance is zero** → direct user to https://api.ponyflash.com/usage to top up credits
## Step 1B: Local Dependency Setup for FFmpeg Tasks
Only do this section when the request needs local editing, subtitle, or export work.
1. First check local dependencies:
```bash
bash "{baseDir}/scripts/check_ffmpeg.sh"
```
2. If the task involves subtitles, do **capability checks**, not just existence checks:
```bash
bash "{baseDir}/scripts/check_ffmpeg.sh" --require-subtitles-filter
```
3. If `ffmpeg` / `ffprobe` or required filters are missing:
- Tell the user what is missing.
- Ask whether the user wants platform-appropriate FFmpeg installation guidance.
- After the user installs FFmpeg, rerun the dependency checks before continuing.
## What this Skill Can Do
| Capability | Resource | Description |
|---|---|---|
| Image generation | `pony_flash.images` | Text-to-image, image editing with mask/reference images |
| Video generation | `pony_flash.video` | Text-to-video, first-frame-to-video, OmniHuman, Motion Transfer |
| Speech synthesis | `pony_flash.speech` | Text-to-speech with voice cloning, emotion control, speed, pitch |
| Music generation | `pony_flash.music` | Text-to-music with lyrics, style, instrumental mode, continuation |
| Model listing | `pony_flash.models` | List available models, get model details and supported modes |
| File management | `pony_flash.files` | Upload, list, get, delete files |
| Account | `pony_flash.account` | Check credit balance, get recharge link |
| Local media editing | `scripts/media_ops.sh` | Clip, concat, transcode, extract audio, frame capture |
| FFmpeg environment checks | `scripts/check_ffmpeg.sh` | Detect ffmpeg / ffprobe and subtitle capabilities |
| Subtitle font prep | `scripts/ensure_subtitle_fonts.sh` | Keep a reusable local copy of the default subtitle font when explicitly requested |
| ASS subtitle prep | `scripts/build_ass_subtitles.py` | Adaptive ASS subtitle generation with pre-wrapping |
## Creative Playbooks (production workflows)
The `playbooks/` directory contains **Creative Playbooks** — step-by-step production workflow guides for specific content types. Playbooks act as a director layer: they tell you **what to create and in what order**, while this SKILL.md tells you **how to execute generation and editing**.
### When to use a playbook
1. **User explicitly requests a playbook by name** → Read the corresponding file from `playbooks/` and follow its workflow.
2. **User asks to see available playbooks** → Read [playbooks/INDEX.md](playbooks/INDEX.md) and display the full list.
3. **User's request is clearly a multi-step production task** → Suggest a matching playbook from [playbooks/INDEX.md](playbooks/INDEX.md) and ask whether to use it.
4. **User's request is a single-step generation or editing task** → Proceed directly with the relevant SDK or FFmpeg capabilitTrust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
Gates applied: no_behavioural_pass.
4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__ponyflash.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f3b4a2a472e | SAFE | B | 89 | first audit |
Questions
What does the Ponyflash skill do?
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Is Ponyflash safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ponyflash access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
What do I need installed to use Ponyflash?
Its own instructions reference ffmpeg and ffprobe. Dependencies are pinned to exact versions.
Which assistants does Ponyflash work with?
Its documentation mentions claude-code, codex, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.